this post was submitted on 21 Aug 2026
431 points (99.5% liked)

Software Gore

6572 readers
621 users here now

Welcome to /c/SoftwareGore!


This is a community where you can poke fun at nasty software. This community is your go-to destination to look at the most cringe-worthy and facepalm-inducing moments of software gone wrong. Whether it's a user interface that defies all logic, a crash that leaves you in disbelief, silly bugs or glitches that make you go crazy, or an error message that feels like it was written by an unpaid intern, this is the place to see them all!

Remember to read the rules before you make a post or comment!


Community Rules - Click to expand


These rules are subject to change at any time with or without prior notice. (last updated: 7th December 2023 - Introduction of Rule 11 with one sub-rule prohibiting posting of AI content)


  1. This community is a part of the Lemmy.world instance. You must follow its Code of Conduct (https://mastodon.world/about).
  2. Please keep all discussions in English. This makes communication and moderation much easier.
  3. Only post content that's appropriate to this community. Inappropriate posts will be removed.
  4. NSFW content of any kind is not allowed in this community.
  5. Do not create duplicate posts or comments. Such duplicated content will be removed. This also includes spamming.
  6. Do not repost media that has already been posted in the last 30 days. Such reposts will be deleted. Non-original content and reposts from external websites are allowed.
  7. Absolutely no discussion regarding politics are allowed. There are plenty of other places to voice your opinions, but fights regarding your political opinion is the last thing needed in this community.
  8. Keep all discussions civil and lighthearted.
    • Do not promote harmful activities.
    • Don't be a bigot.
    • Hate speech, harassment or discrimination based on one's race, ethnicity, gender, sexuality, religion, beliefs or any other identity is strictly disallowed. Everyone is welcome and encouraged to discuss in this community.
  9. The moderators retain the right to remove any post or comment and ban users/bots that do not necessarily violate these rules if deemed necessary.
  10. At last, use common sense. If you think you shouldn't say something to a person in real life, then don't say it here.
  11. Community specific rules:
    • Posts that contain any AI-related content as the main focus (for example: AI “hallucinations”, repeated words or phrases, different than expected responses, etc.) will be removed. (polled)


You should also check out these awesome communities!


founded 3 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] Entertainmeonly@lemmy.blahaj.zone 111 points 1 day ago (4 children)

Auto fill likes to put a space after the name that often will make these forms freak out.

[–] dohpaz42@lemmy.world 60 points 1 day ago (4 children)

Not always. My mortgage company uses a software where it treats the password as invalid if it’s autofilled. I have to copy and paste the password into the box to remove the error.

Why people and companies need to make things purposefully difficult is beyond me. This shit is decades old and solved. Yet, they’re still constantly broken.

[–] kuberoot@discuss.tchncs.de 4 points 13 hours ago (1 children)

From my experience, I think this also happens because of badly written code, where it tries to detect user input to do validation, but it handles events incorrectly and sees autofill as invalid.

[–] LastYearsIrritant@sopuli.xyz 1 points 5 hours ago

I found that a lot of banks reject it unless both of the fields have been active inputs.

So do the auto fill, then click each field so it thinks they were both used, then click login.

Dumb, but two of my financial institutions require it.

[–] brb@sh.itjust.works 52 points 1 day ago

What usually works is adding a character at the end of the autofilled password and then removing it

[–] MonkderVierte@lemmy.zip 9 points 20 hours ago* (last edited 20 hours ago)

Security theater.
"Look, boss, i made thing more secure!"

[–] nocturne@slrpnk.net 23 points 1 day ago (2 children)

My old bank would not allow pasted passwords, nor autofill. For a while PayPal was the same way.

[–] acockworkorange@mander.xyz 8 points 19 hours ago

https://github.com/marcos10pc/dont-f--with-paste-bookmark

Don't fuck with paste - a bookmarklet for those occasions.

[–] cmnybo@discuss.tchncs.de 17 points 1 day ago

Many password managers have a function where they can fill the password by sending key presses for troublesome sites like that.

[–] eatham@aussie.zone 16 points 1 day ago (1 children)

Spaces are valid within names.

[–] KairuByte@lemmy.dbzer0.com 7 points 22 hours ago (2 children)

Are they valid after names? I mean I suppose they could be, but how could you ever, and I mean ever, write out the name in that case?

[–] eatham@aussie.zone 24 points 22 hours ago (3 children)

No but the software should just remove excess whitespace instead of complaining

[–] lemmyvore@feddit.nl 11 points 21 hours ago (1 children)
[–] 0x0@lemmy.zip 1 points 18 hours ago* (last edited 18 hours ago) (1 children)

11 i thought all alphabets have been encoded in Unicode?
15 Murica and Brazil have no rules whatsoever so i guess it can happen.

[–] gandalf_der_13te@feddit.org 1 points 4 hours ago* (last edited 4 hours ago)

some people don't even have a native writing system so i guess their name is not canonically mapped in unicode characters either. every attempt to write it down is just an approximation.

[–] balsoft@lemmy.ml 9 points 21 hours ago (1 children)

No it shouldn't. Text field entry should have two properties: (1) accept any UTF-8 string, (2) do not modify that string.

If you want to make sure people don't make mistakes, take all your current validation code and turn it into a huge red warning that pops up if you try to continue with an "incorrect" field, asking you to double-check before proceeding. In the OP case it would be "You have entered an uncommon name", in case of extra whitespace it would be "There is whitespace after the name". Let the person themselves edit the field, don't change the text automatically at all.

If those fields are used for anything other than interacting with the person entering them, validate during submission. In this case, charge a $1 HOLD on the credit card using the info provided.

Anything other than that will lead to someone somewhere having an issue like the OP.

[–] eatham@aussie.zone 6 points 21 hours ago (1 children)

No, you should definitely sanitize the names if you are going to display them anywhere. You don't need JS to execute just because it's in someone's name, and that would also cause it to display incorrectly as the JS portion would not be shown. Getting rid of excess whitespace is fine aswell as it does not change the name

[–] balsoft@lemmy.ml 12 points 21 hours ago* (last edited 20 hours ago) (1 children)

That's just awful security practices. You must not replace proper code/data separation with user input sanitization. If you are just pulling names from a database and inserting them into your DOM directly you're doing things majorly wrong and half your codebase probably needs rewriting from scratch.

If your stack does not support code/data separation, you should escape at the point of use/point of interface with other software, not at the point of user data entry.

You should not "sanitize" something as personal as a name. It is up to the individual to identify themselves as they see fit, whether it is some weird legal name or just how they want to present. For every "rule" about names you can think of, there will be an exception somewhere.

In fact, even splitting up the name field into "first name" and "last name" is already wrong. It should just be "name". If you need there to be a separate "first name" and "last name" for some reason (e.g. an external system which requires it), allow leaving either one as empty. Bonus points if you have independent "legal name" and "how would you like to be called" fields.

Getting rid of excess whitespace is fine aswell as it does not change the name

As a responsible developer you must not assume this. Especially if your software interacts with other systems. You never know what dumb shit some other system has got up to, maybe a clerk somewhere accidentally entered someone's name with a space and that person desperately needs to use your software while they're getting things fixed.

As an immigrant, I have been personally strongly inconvenienced by user input validation very often. For example, a tax agency system (which has my passport number recorded with a space) rejected automatic declarations from my bank (where the system did not allow spaces in the passport number) so I had to fill my tax declarations manually for a while. Or my bank rejecting bills from the water utility because the utility's system required entering two surnames, and I only have one, so they just put it in there twice. The amount of services which reject my pretty normal-looking self-hosted email address with "enter a valid email address" (presumably it must end in @gmail.com or @outlook.com) is staggering. This kind of bullshit is widespread and it needs to stop. You as a developer don't know better than the person entering the data about themselves.

[–] Pieisawesome@lemmy.dbzer0.com 5 points 16 hours ago

100% this.

So many places do these things wrong and just make wild assumptions based on their limited PoV.

I just spent a month adding international phone, name, and postal code support to a legacy app at my job.

They weren’t even consistent with their enforcement inside of the app.

Don’t add validation for anything unless you understand 100% of the cases. You should use premade libraries or tools in most cases because you will do it incorrectly.

The rules around passwords are equally as dumb

[–] tgxn@lemmy.tgxn.net 9 points 22 hours ago
[–] bhamlin@lemmy.world 7 points 22 hours ago (1 children)

Who are you to judge that my name isn't valid? I can be " Bart 2" if I want to be.

[–] KairuByte@lemmy.dbzer0.com 3 points 11 hours ago (2 children)

Does your name include the quotes? >.>

[–] thethunderwolf@lemmy.dbzer0.com 2 points 9 hours ago

only one of them obviously

[–] bhamlin@lemmy.world 1 points 8 hours ago

Only the last one

[–] hig13@lemmy.world 6 points 22 hours ago (4 children)

Couldn't you just make it so the text box doesn't accept spaces to prevent that? Why allow a character to be input that makes the field invalid?

[–] gwl@lemmy.blahaj.zone 25 points 20 hours ago* (last edited 20 hours ago)

Yeah, that's also a bad idea, there's plenty of (mostly none-western) forenames that contain spaces, and plenty of surnames that contain spaces all over the world (Charles de Gaul, Guy Manuel de Hommen-baron)

All they really need to do is to onSubmit do a .trim() to the name

[–] FooBarrington@lemmy.world 15 points 21 hours ago (1 children)

Because even if a space at the end of the name should be considered invalid, people can have names with spaces inside.

[–] Whats_your_reasoning@lemmy.world 8 points 19 hours ago

This is true. I know someone with a legal first name that's two words. He's a kid I work with. His parents made a point that his name isn't one or the other, it's both, and we are to address him as such.

To my understanding (as a non-tech person who consumes tech-related media), name fields are commonly culturally biased. Usually it impacts last names, which can vary in size and layout across the world, sometimes including hyphens (which some systems don't like either.) Super short or long names also run into problems. Not everyone has one first name, one middle name, and one last name, but a lot of systems aren't designed to handle that kind of variation.

[–] MonkderVierte@lemmy.zip 7 points 20 hours ago (1 children)

Nah, backend is hard, and they only know JS.

[–] Kushan@lemmy.world 6 points 20 hours ago (1 children)

As a primarily backend engineer, I think the opposite here. The backend makes sense, JS is just a nightmare.

[–] MonkderVierte@lemmy.zip 3 points 19 hours ago* (last edited 16 hours ago)

From the typical web developer' view of course. They don't even know the <form><input type="submit"> thing anymore nowadays, neither the people who developed their framework. Can't apply for a job, because the js-form has a bug!

[–] dev_null@lemmy.ml 7 points 21 hours ago* (last edited 21 hours ago) (2 children)

Of course you can. But whoever developed the form didn't care about their craft.

[–] tigeruppercut@lemmy.zip 4 points 19 hours ago* (last edited 19 hours ago)

Japan has gotten a lot better but you still run into shit for this sometimes. First and middle names often have to be input without a space, so you end up with Johnwendell Anderson. And sometimes forms require names to be input with the Japanese phonetic alphabet (which lacks a lot of letters in English), and then if it doesn't match some document you need to verify an online input there can be trouble. So Jeeves would become Jiibuzu, and good luck matching that to your passport at the airport.

[–] boonhet@sopuli.xyz 3 points 19 hours ago (1 children)

Or they work for a for-profit company so there's KPIs on how much they go under/over estimate on a task and either someone else did the estimate, or coworkers judge them for conservative estimates, so they did it as quickly as possible

[–] dev_null@lemmy.ml 3 points 19 hours ago

That's not an "Or" though, that's a "Probably because"

[–] lime@feddit.nu 13 points 1 day ago (1 children)

what if my name has a space at the end though?

[–] Birch@sh.itjust.works 6 points 1 day ago